hi out there
I just got a bit surpriesed when I was chasing a "hit" in a ACL on a firepower 4110 running FTD OS 6.6.1 - we have ACL whcih is pretty high - near the top - of the policy - which is pretty open but based on AD-group membership.
When I ran a packet tracer to verify where I get a hit it was on this ACL and not on the one I expected. Can some confirm to me that this is just because that the Packet Tracer under FTD is not capable of using the AD group membership - which would make sense.
br ti
Solved! Go to Solution.
That's an interesting outcome. On the surface I would agree with your observation although I haven't seen that particular limitation discussed or documented before now.
I'd recommend opening a TAC case to confirm it and making sure a bug is filed (if there's not one already).
That's an interesting outcome. On the surface I would agree with your observation although I haven't seen that particular limitation discussed or documented before now.
I'd recommend opening a TAC case to confirm it and making sure a bug is filed (if there's not one already).